Checkmarx: Security vulnerability in uploading file (Cordova_File_Disclosure)

Viewed 65

I have the following code as input file dialog for user to upload a file:

<input #FileSelectInputDialog id="UserFile" type="file" style="display:none" (change)="onFileChange($event)"  [multiple]="false" [accept]="'application/vnd.ms-excel,application/vnd.openxmlformats-officedocument.spreadsheetml.sheet'">

It's being flagged as having vulnerability by Checkmarx.

enter image description here

In my angular code, I read the file as follows:

reader.readAsBinaryString(target.files[0]);

The thing is, user will need to upload the file from their local drive, and I cannot limit which folder in their laptop that they have to put the file. I'm not sure also on how to "sanitize" the input filename, as target itself is an object.

enter image description here

Any ideas?

0 Answers
Related